GoMedPay
  • How It Works
  • RCM Hub
  • Ledgr
  • Free Snapshot
  • Resources
    • Rejections Snapshot Free 3-page rejection diagnostic — runs in your browser
    • Free Templates RCM checklists, trackers & appeal letters
    • Switching Cost Calculator Model your monthly switch fees vs the benchmark

    • News & Articles Medical aid updates & regulatory news
    • RCM Knowledge Centre Verified answers for SA practitioners
  • COIDA & RAF
  • About
  • Pricing
  • Book an Unpaid Claims Review
Legal

POPIA Compliance Statement

Effective date: 10 June 2026  ·  GoMedPay

GoMedPay is committed to compliance with the Protection of Personal Information Act 4 of 2013 (POPIA), which commenced on 1 July 2021. This statement explains how GoMedPay meets its obligations as both a Responsible Party and, in certain circumstances, as an Operator under POPIA.

1. GoMedPay's roles under POPIA

As a Responsible Party

GoMedPay is the Responsible Party for personal information collected through the GoMedPay website, including inquiry form submissions and newsletter subscriptions. We determine the purpose and means of processing this information.

As an Operator

When GoMedPay performs revenue cycle management services for a medical practice, we may process patient billing and claims data on behalf of that practice. In this capacity, GoMedPay acts as an Operator under POPIA — the practice remains the Responsible Party for its patient data, and GoMedPay is bound by a Data Processing Agreement (DPA) with the practice before any data is accessed. No patient data is accessed by GoMedPay without a signed DPA in place.

2. Information Officer

Name: Andile Memela CA(SA) CIA

Role: Information Officer, GoMedPay

Email: [email protected]

Website: www.gomedpay.co.za/about/

The Information Officer is responsible for ensuring GoMedPay's compliance with POPIA, handling data subject requests, and liaising with the Information Regulator of South Africa. If you have a question or request relating to your personal information, contact the Information Officer at the email address above.

3. Your rights as a data subject

Under POPIA sections 23–25, you have the following rights:

Right of access (s. 23)

You may request a description of the personal information we hold about you and request a copy of that information.

Right to correction or deletion (s. 24)

You may request that inaccurate, misleading, out-of-date, incomplete, or unlawfully processed information be corrected or deleted. Deletion is subject to our legal retention obligations.

Right to object (s. 11(3))

You may object to the processing of your personal information on grounds relating to your particular situation. You may object to direct marketing at any time using the unsubscribe link in any marketing email.

Right to withdraw consent

Where we rely on your consent to process personal information (e.g. newsletter subscriptions), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

Right to complain to the Information Regulator

You may lodge a complaint with the Information Regulator of South Africa if you believe your rights under POPIA have been infringed.

To exercise any of these rights, please contact the Information Officer at [email protected]. We will respond within the time periods prescribed by POPIA.

4. How to lodge a complaint with the Information Regulator

If you are not satisfied with how GoMedPay has handled your personal information or your rights request, you may submit a complaint to the Information Regulator of South Africa:

  • Website: inforegulator.org.za
  • Email: [email protected]
  • Postal address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

Complaints may also be submitted using Form 5 (Complaint Form) available on the Information Regulator's website.

5. Security measures

GoMedPay has implemented the following technical and organisational measures to safeguard personal information:

  • All data is transmitted over HTTPS with TLS encryption enforced by HTTP Strict Transport Security (HSTS)
  • Session tokens and CSRF tokens are served as secure, same-site cookies only
  • Production application infrastructure is hosted on Railway with access-controlled deployments
  • Error monitoring is configured to exclude personally identifiable information from error reports
  • Newsletter subscriptions use a double opt-in flow — no marketing emails are sent until the subscriber confirms their email address
  • Client practice data accessed under a DPA engagement is stored only for the duration of the engagement and deleted upon engagement closure
  • Staff with access to production data are limited to authorised GoMedPay team members

6. Newsletter marketing consent

GoMedPay uses a double opt-in process for all newsletter subscriptions. When you subscribe, you receive a confirmation email with a unique link. Marketing emails are only sent after you click that link. Your consent timestamp and confirmation record are stored as a POPIA-compliant audit record. You may unsubscribe at any time using the link at the bottom of any marketing email.

7. Data Processing Agreements

GoMedPay's third-party service providers (SendGrid, Railway, Cloudflare) each operate under contractual terms that restrict them from using GoMedPay data for any purpose other than providing their services to us. Transfers to providers outside South Africa are governed by Standard Contractual Clauses. A list of current processors is maintained in our Privacy Policy.

8. Ongoing compliance

GoMedPay reviews this Compliance Statement and its associated Privacy Policy annually or when material changes to processing activities occur. The last review date is reflected in the effective date at the top of this page.

Related: Privacy Policy  ·  Terms of Service

GoMedPay

CA(SA)-led recovery of rejected and short-paid medical-aid claims for SA private specialist practices. Section 59 billing-trail readiness and IFRS financial intelligence — CA(SA) founded, CIA-rigoured, POPIA-aligned operator controls.

GoMedPay

Services
  • Unpaid Claims Review
  • Front-Office SOPs
  • Ledgr
  • Revenue Recovery Bridge
  • GoMed-LongCycle
Company
  • About Us
  • How It Works
  • Pricing
  • Book a Review
  • News & Articles
Contact
  • [email protected]
  • [email protected]
  • 083 400 5908
  • Mon–Fri, 8am–5pm SAST
Legal
  • Privacy Policy
  • Terms of Service
  • POPIA Compliance

© 2026 GoMedPay. All rights reserved.
Built with CA(SA) institutional-grade standards
GoMedPay uses anonymous analytics to improve the site. No claim data, no patient data. Privacy policy.